
Plenty of companies that had never bought a CrowdStrike license still lost most of a working day on 19 July 2024. Their airline was grounded, their payroll provider was down, the hospital system their employees used was working on paper, or the managed service provider that ran their help desk was rebooting machines one at a time. On paper, none of those companies had a CrowdStrike dependency. In practice, they did.
That gap between the vendor list and the dependency map is where most third-party risk programs are weakest. Procurement knows who you pay. Security knows who touches your data. Neither list tells you which outside parties could stop a critical service, how quickly, or whether several of them rely on the same thing underneath.
The scoring table below is the part most programs are missing.
Start from critical services, not the vendor master file
A mid-size company's accounts-payable vendor file can hold several thousand names. Assessing them all equally is how third-party programs drown in questionnaires. Start instead with the handful of critical business services your business impact analysis identified, and trace each one outward:
- Inputs: raw materials, components, finished goods, packaging.
- Technology: software-as-a-service platforms, hosting, network carriers, payment processors, managed service providers.
- Logistics: carriers, third-party warehouses, ports, customs brokers.
- Facilities and utilities: landlords, power, water, fuel, building systems maintenance.
- People and expertise: staffing agencies, outsourced call centers, the one contractor who understands the legacy system.
Expect surprises. Some critical dependencies never appear in accounts payable: an open-source library, a parent company's shared service, a utility billed through the landlord, a payment processor paid by netting fees out of settlements. Record them anyway. A dependency annex belongs in the continuity plan itself, and our annotated sample plan table of contents shows where it fits.
Score criticality, then tier
Spend is a poor proxy for criticality. A $40,000-a-year labeling software vendor whose system prints every outbound shipping label can matter more than a $2 million marketing agency. Score each dependency on what happens when it fails.
| Criterion | Weight | Score 1 | Score 3 | Score 5 |
|---|---|---|---|---|
| Impact on a critical service | 3 | Supports no critical service | Degrades one critical service | Stops one or more critical services |
| Time to impact | 2 | Weeks before anyone notices | Several days | Within hours |
| Substitutability | 3 | Alternatives ready, days to switch | Alternatives exist, weeks to qualify | Sole source, or months to replace |
| Data and access | 2 | No sensitive data or network access | Limited data or access | Regulated data or privileged access |
| Regulatory or contractual exposure | 1 | None | Customer contract terms affected | Regulatory reporting or license at stake |
| Concentration | 1 | Supports one minor process | Supports several processes | Supports several critical services |
Multiply each score by its weight and add them up, for a total between 12 and 60. Then tier:
| Tier | Weighted score | Treatment |
|---|---|---|
| Tier 1: Critical | 45 to 60 | Full due diligence, tested recovery, alternates, quarterly review |
| Tier 2: Important | 32 to 44 | Due diligence, documented workaround, annual review |
| Tier 3: Standard | 20 to 31 | Baseline questionnaire, review at renewal |
| Tier 4: Low | 12 to 19 | Contract hygiene only |
Add one override. Any dependency that is the sole source for a critical service, where switching would take longer than that service's recovery time objective, is Tier 1 regardless of its score. Weighted averages have a way of smoothing over the single fact that matters most.
The weights are a starting point; a hospital might weight data and access more heavily. Agree on them once with operations, procurement and risk, then stop relitigating them supplier by supplier.
Fourth parties and concentration risk
Your vendors have vendors. Two questions matter: which of them do your Tier 1 suppliers depend on, and how many of your suppliers depend on the same ones?
Concentration shows up in predictable places: one cloud provider or region hosting several of your SaaS platforms, one payment processor behind multiple sales channels, a shared logistics hub, a single specialized component plant, one port of entry. NotPetya in 2017 showed how far one company's outage can travel. Maersk's systems were crippled, and disruption at its terminals reached shippers who had never considered Maersk's IT to be their risk. The Colonial Pipeline shutdown in 2021 did something similar with fuel, producing shortages across parts of the Southeast that landed on businesses whose only link to the pipeline was the trucks they relied on.
To find concentration, ask each Tier 1 vendor to name its own critical dependencies: hosting provider and region, key subprocessors, primary manufacturing sites, logistics providers. Put the answers in a simple matrix of your vendors against their dependencies. Columns with many marks are your concentration points. You will not get complete answers, and you do not need them. Even a partial view usually reveals two or three places where several "independent" suppliers share a single point of failure.
Regulators are pushing in the same direction. The EU's Digital Operational Resilience Act, which will apply to financial entities from 17 January 2025, requires a register of ICT third-party arrangements and an assessment of concentration risk. For the cyber side of supply chain risk, NIST SP 800-161 Rev. 1 offers a detailed framework that scales down better than its length suggests.
What to ask vendors, and what the SOC report leaves out
Most vendors answer due diligence by sending a SOC 2 Type II report. Read it, but read it for what it is: an auditor's opinion on whether the described controls operated effectively over a period, measured against the Trust Services Criteria in scope. Three limits matter for resilience:
- Availability may be out of scope. Security is the only required criterion. Many reports never test availability or recovery at all.
- Subservice organizations are often carved out. If the vendor's hosting provider is carved out, the report says nothing about it, and the hosting provider is frequently where the outage starts.
- Complementary user entity controls are your job. The report lists controls the vendor assumes you operate. If you do not operate them, its conclusions do not fully cover you.
Check the report period too. A report that ended nine months ago needs a bridge letter, and even then it describes the past.
None of that makes SOC reports useless. It makes them one input. For Tier 1 vendors, ask directly:
- What is your recovery time for the specific service we use, and when did you last test it end to end?
- What did that test show, and what did you fix afterward?
- Which hosting providers, regions and subprocessors does our service depend on?
- If many customers are affected at once, how do you prioritize restoration, and where are we in that order?
- What manual or degraded service can you offer while systems are down?
- How quickly, and how, will you notify us of an incident affecting our service or data?
- What happens if your own primary supplier fails?
- Who, by role, is our contact during an incident, and how do we reach them if your systems are down?
Vague answers to the first and fourth questions are themselves an answer.
Alternate sourcing, built before you need it
Alternatives take time to build, usually longer than the disruption you are planning for. The options, roughly from cheapest to most expensive:
- A documented manual workaround for a software dependency, tested once a year.
- Safety stock for physical inputs, sized to the time it would take to qualify a new source.
- A qualified but dormant second source, approved and set up in your systems, with small periodic orders to keep the relationship alive.
- A capacity reservation with a second supplier, paid for whether or not you use it.
- Active dual sourcing, with volume split across suppliers in different regions.
COVID-19 exposed sole-sourced, single-region supply chains across nearly every industry; our pandemic continuity briefing covers what that period taught. Winter Storm Uri in 2021 made a narrower point. When Gulf Coast petrochemical plants shut down in the freeze, buyers of plastic resins found that several of their "different" suppliers were exposed to the same weather.
In regulated industries such as food and medical devices, qualifying a new source can take months. Start those conversations long before the disruption.
Contract clauses worth fighting for
| Clause | What it should do | Watch for |
|---|---|---|
| Continuity and recovery | Require the vendor to maintain and test its continuity plan and share results | "Commercially reasonable efforts" with no testing duty |
| Incident notification | Set a firm notice window for incidents affecting your service or data | Notice only after the vendor "confirms" a breach |
| Subcontractor changes | Require notice before material subprocessor or hosting changes | Silent moves to a new provider or region |
| Recovery commitments | Tie service levels to recovery times, with real remedies | Credits capped at a fraction of one month's fee |
| Force majeure | Keep it narrow, so a foreseeable outage does not excuse a vendor with no tested plan | Language covering "any failure of third-party systems" |
| Allocation | Define how scarce supply is shared among customers | Allocation left to the vendor's discretion |
| Exit and transition | Guarantee data return and transition help | Fees or delays that make leaving impractical |
| Insurance | Require meaningful coverage, including cyber where relevant | Limits too small to matter |
Your own insurance is part of the picture. Contingent business interruption coverage can respond to losses caused by a supplier's disruption, but its conditions and exclusions vary widely. Our briefing on business interruption insurance lists what to confirm with your broker.
Monitoring between reviews
An annual questionnaire captures one day a year. For Tier 1 and Tier 2 suppliers, watch for signals in between:
- Financial strain: credit downgrades, sudden changes to payment terms, layoffs, late deliveries.
- Ownership changes: acquisitions often bring platform migrations and staff departures.
- Operational drift: missed service levels, turnover in your account team, slower responses.
- Security events: breach disclosures, sanctions listings, external cyber ratings (treat these as prompts, not verdicts).
- Hazards: severe weather, geopolitical disruption or regulatory action near key sites.
Tie each signal to an action: a call from the relationship owner, an off-cycle review, or activating an alternate.
A 90-day starting plan
- Days 1 to 30: List critical services from the BIA. Trace each one's dependencies across the five categories above. Agree on scoring weights with operations, procurement and risk.
- Days 31 to 60: Score and tier every dependency you found. Apply the sole-source override. Send the eight questions to Tier 1 vendors and ask for their key dependencies.
- Days 61 to 90: Build the concentration matrix. Pick the three Tier 1 dependencies with the weakest alternates and fund one fix for each: a workaround, safety stock or a qualified second source. Queue the contract clauses for the next renewal of every Tier 1 agreement.
The decision rule underneath all of it: if losing a supplier would stop a critical service for longer than its recovery time objective, and you have no tested alternative, you have found your next project.



